Yes. Lusha’s GDPR compliance is certified by ePrivacyseal GmbH, a European independent auditor, and its CCPA compliance is validated by TrustArc. Lusha holds SOC 2 Type II, ISO 27001, ISO 27017, ISO 27701, ISO 31700 and ISO 42001, and TRUSTe Responsible AI certification. It is registered with the California Data Broker Registry, collects business contact information only, and gives anyone whose details are in the database the right to see, correct or remove them. Certificates, the Data Processing Agreement, Standard Contractual Clauses and the subprocessor list are on the Trust Center.
Key takeaways
- Certified, not self-declared. GDPR by ePrivacyseal GmbH, CCPA by TrustArc, information security and privacy by accredited ISO auditors, SOC 2 Type II by an independent auditor.
- Business contact data only. Name, title, work email, business phone, company. The kind of information on a business card. No consumer data, no scraping of social networks.
- Rights built in. Opt-out and Do Not Sell links in every footer, Article 14 notifications, automated handling of access and deletion requests, a Do Not Call flag on every phone record.
- Your own obligations still apply. Lusha’s compliance covers how the data is collected and processed. Your outreach has its own legal basis, and the compliance guide walks through it.
Is Lusha GDPR compliant?
Yes. Lusha’s GDPR compliance is certified by ePrivacyseal GmbH. In practice that covers: a Data Processing Agreement available to every customer, Standard Contractual Clauses for transfers outside the EU, Legitimate Interest Assessments conducted and documented for the processing of business contact data, Data Protection Impact Assessments available on request, Article 14 notification mechanisms so individuals learn their business details are in the database, and automated handling of data subject requests for access, correction and deletion. Personal data of EU customers is stored mainly in EU regions. Lusha also holds ISO 27701, the privacy information management extension to ISO 27001, which is the standard most closely mapped to GDPR controls.
Is Lusha CCPA compliant?
Yes. Lusha’s CCPA and CPRA compliance is validated by TrustArc. That covers Do Not Sell mechanisms and opt-out support, processing of consumer rights requests for access, deletion and opt-out, transparency about what is collected, how it is used and with whom it is shared, and service provider agreements that meet CCPA standards. Lusha is registered with the California Data Broker Registry, which is the public register California requires of any business that sells personal information it did not collect directly from the consumer. US data is stored in US regions.
Which certifications does Lusha hold?
| Certification | What it covers | Who audited it |
|---|---|---|
| SOC 2 Type II | Security, availability, confidentiality and privacy controls, tested over a period | Independent auditor; report available under gated access |
| ISO 27001 | Information security management system | Accredited third party, ANAB vetted |
| ISO 27017 | Cloud-specific security controls on top of 27001 | Accredited third party |
| ISO 27701 | Privacy information management, the GDPR-aligned extension to 27001 | Accredited third party |
| ISO 31700 | Privacy by design for consumer goods and services | Accredited third party |
| ISO 42001 | AI management system, governance of AI capabilities | Accredited third party |
| TRUSTe Responsible AI | Data governance alignment with ethical standards and regulation for AI | TRUSTe |
| GDPR | Certified compliance | ePrivacyseal GmbH |
| CCPA / CPRA | Validated compliance | TrustArc |
Source: Lusha Trust Center, compliance page, accessed October 7, 2026.
Where does Lusha’s data come from?
Four sources, described on the data sources page. Members of the Lusha Community, who opt in and share business contact details from email headers and signatures. Licensed partners with established business directories, each vetted for security and GDPR and CCPA compliance. Publicly available business information. And Lusha’s own analysis, which completes patterns such as company email formats. Lusha does not scrape professional networks or social platforms and does not buy from data brokers. The data is business contact information: name, title, company, work email, business phone.
Is Lusha a data broker?
Under California’s definition, yes, and it is registered as one. The California Data Broker Registry lists businesses that sell personal information they did not collect directly from the individual. Registration is what puts a business under the state’s transparency and deletion requirements, which is the point of the register. Lusha’s listing, its Do Not Sell mechanism and its removal form are the practical result.
Where is Lusha’s data stored?
Personal data of EU customers is stored mainly in EU regions. US data is stored in US regions. Cross-border transfers use Standard Contractual Clauses, with Transfer Impact Assessments conducted and data flows documented. The Transfer Impact Assessment is linked in the site footer.
How do I remove my information from Lusha?
Through the removal request form, also linked as Opt Out and Do Not Sell My Info in the footer of every page. Once processed, the record is added to a suppression list and Lusha notifies customers who previously received it. The same Privacy Center lets anyone view and correct their information. Lusha also sends Article 14 notifications where the law requires, so people learn their business details are in the database before a customer uses them.
Does Lusha show Do Not Call status?
Yes. Every phone record carries a Do Not Call flag, returned as a field through the Workspace, the API and the MCP, so a rep knows before dialing and a dialer can suppress flagged numbers automatically. US mobile numbers carry TCPA obligations; the flag helps, and your own obligations still apply.
Which compliance documents can I get?
Available for download or on request from the Trust Center: the SOC 2 Type II report (gated), ISO certificates, the Data Processing Agreement, Standard Contractual Clauses, the subprocessor list, the security whitepaper, the privacy whitepaper, and a penetration test summary under NDA. The Trust Kit keeps the current set of third-party audits and certifications in one place.
Is Lusha a GDPR-friendly choice for outreach in Europe?
Yes, with one condition. Lusha’s certification covers how the data is collected and processed. Your outreach has its own legal basis under GDPR, which you document for your own processing. The compliance guide in the Knowledge Hub walks through how to do that with Lusha data, and every phone record’s Do Not Call status is part of the answer. For how other vendors compare on compliance, see Best privacy compliant B2B data providers in the US.
FAQ
Is Lusha GDPR compliant?
Yes. Certified by ePrivacyseal GmbH, with a DPA, SCCs, documented Legitimate Interest Assessments, Article 14 notifications and automated data subject request handling. Lusha also holds ISO 27701.
Is Lusha CCPA compliant?
Yes. Validated by TrustArc, with Do Not Sell mechanisms, consumer rights request processing and registration with the California Data Broker Registry.
Which ISO certifications does Lusha hold?
ISO 27001, 27017, 27701, 31700 and 42001, all audited by accredited third parties. Plus SOC 2 Type II and TRUSTe Responsible AI.
Does Lusha collect personal data?
Business contact information only: name, title, company, work email and business phone. No consumer data, no scraping of social networks.
How do I opt out of Lusha?
Through the removal request form, linked as Opt Out and Do Not Sell My Info in every page footer. The record goes on a suppression list and customers who received it are notified.
Can I use Lusha data for outreach in the EU?
Yes. Lusha’s certification covers how the data is collected and processed. Your outreach needs its own documented legal basis, and the compliance guide covers that side.
Sources
- Lusha Trust Center, compliance page, accessed Oct 7, 2026
- Lusha FAQ, compliance and privacy section, accessed Oct 7, 2026
- Lusha data sources page, accessed Oct 7, 2026
